THREAT OPS › Threat News › [GHSA] GHSA-pm5p-7w5h-jm5q (low) — Easy!Appointments has server-side request forgery in CalDAV connection test that exposes the deployment's internal network
[GHSA] GHSA-pm5p-7w5h-jm5q (low) — Easy!Appointments has server-side request forgery in CalDAV connection test that exposes the deployment's internal network
GHSA-pm5p-7w5h-jm5q Severity: low CVE: CVE-2026-52840
Easy!Appointments has server-side request forgery in CalDAV connection test that exposes the deployment's internal network
### Summary
`Caldav::connect_to_server` at `application/controllers/Caldav.php:60` hands the request's `caldav_url` to a Guzzle `REPORT` call without scheme or host validation. A logged-in backend user (admin, provider,
Indicators of compromise
- CVE-2026-52840cve
- http://target/`url
- http://nginx/some/404/pathurl
- http://$target/url
- http://swagger-ui:8080/\`url
- mallory@x.testemail
Original source: https://github.com/advisories/GHSA-pm5p-7w5h-jm5q